Every so often an attack campaign arrives that is remarkable not for its sophistication but for its absence of it. The Snowflake campaign, which began surfacing in May 2024, is the definitive modern example. There was no zero-day, no malware on the victim's network, no clever lateral movement. There was a username, a password, and an account without multi-factor authentication.
The credentials came from infostealer malware — the quiet, unglamorous plague that sits on infected personal and contractor machines harvesting every saved login in the browser. Some of the credentials used were years old. They still worked, because the accounts they opened had never been given a second factor, and because nobody had thought of a data-warehouse tenancy as a crown-jewel system. Snowflake itself was not breached; the attackers walked into customer environments, one company at a time, and copied out whatever those companies had stored there. By the campaign's end roughly 165 organisations were implicated, and the resulting disclosures — Ticketmaster and Santander in the first wave, AT&T in July — made it the year's largest theft of consumer data.
The uncomfortable part is how ordinary every failure was. Cloud platforms had been sold on the promise that security was included; the fine print always said shared. Customers configured the tenancy, chose the authentication, and owned the outcome. May 2024 is when the industry discovered how many had read the brochure rather than the contract — and it is the reason enforcement of MFA, rather than the mere availability of it, became the default across major platforms within the year.
Ascension goes back to handwriting
On May 8, ransomware struck Ascension, one of America's largest non-profit health systems, spanning roughly 140 hospitals. Electronic health records went offline, ambulances were diverted, medication administration reverted to paper, and clinical staff spent weeks working without the systems their workflows are built around. Investigators traced the entry point to an employee inadvertently downloading a malicious file. Health systems remain the most consequential ransomware target: the disruption is not an inconvenience but a clinical risk, and the recovery is measured in weeks of degraded care.
Dell's 49 million records
Dell disclosed that a threat actor had obtained records relating to roughly 49 million customer orders — names, physical addresses, and hardware details — not by breaking in, but by abusing a partner portal's API, reportedly registering as a partner and querying it at scale until the dataset was assembled. No malware, no exploit. It was a lesson in a category defenders systematically under-weight: an interface that answers too many questions too quickly is a breach waiting for someone patient enough to ask.
CERT-In flags an intrusion at BSNL
On May 20, 2024, India's Computer Emergency Response Team reported a possible intrusion and data breach at BSNL — a fact later confirmed by the government in a reply to Parliament. BSNL is not merely a telecom operator; it is the state-owned carrier serving rural districts, government offices, and strategic installations where private networks do not reach. Details were sparse at the time and remained so, which was itself part of the story: the incident surfaced through official channels rather than corporate disclosure, and Indian users learned about it largely through parliamentary answers. It was an early argument for what the DPDP framework would eventually require — that breach notification be an obligation to the affected, not a disclosure made at the breached party's convenience.
GPT-4o arrives, then Sky is paused
OpenAI announced GPT-4o on 13 May 2024: one model handling text, audio and vision natively, released to ChatGPT's free tier and answering speech at roughly conversational latency. The demo's warmth became the story. OpenAI paused the "Sky" voice as the comparisons spread, and Scarlett Johansson's statement followed the next day — she had declined requests to license her voice, she said, and the result sounded eerily similar to it. OpenAI maintained that Sky belonged to a different professional actress, cast before any approach was made to her. A day after GPT-4o, Google I/O placed AI Overviews atop Search; screenshots of answers recommending glue in pizza sauce travelled further than the rollout itself, and Google's head of Search replied at month's end that some circulating examples were fabricated, attributing the rest to misread queries and thin source material. On 21 May Anthropic published Scaling Monosemanticity, mapping millions of interpretable features inside Claude 3 Sonnet — the paper that moved interpretability from a research curiosity to something buyers now ask about.
A screenshot database on every desktop
Microsoft introduced Copilot+ PCs on 20 May 2024 and, with them, Recall: a feature that periodically captured the screen, read the images on-device, and made months of them searchable. Security researchers objected the following day, Kevin Beaumont arguing that the design undermined Windows security; hands-on testing soon showed the index sitting in the user's own profile as a readable database, which turned every infostealer into a retrospective one. Microsoft answered that snapshots never left the machine and were protected by device encryption. The counter was that encryption at rest does nothing about malware already running as the logged-in user. The timing was uncomfortable: on 3 May Satya Nadella had told staff that where security conflicted with any other priority, security won. Recall was delayed within weeks, and what eventually shipped had been re-engineered around an encrypted enclave. Mid-month, Palo Alto Networks agreed to buy IBM's QRadar SaaS assets for $500 million in cash, folding another detection stack into a shrinking set of platforms.
⏳ Time capsule — May 2024
- OpenAI's GPT-4o demo and Google's Gemini announcements dominated the technology conversation; security teams began asking who owned the prompts.
- Ticketmaster's breach arrived mid-tour-season, giving the story an unusually engaged public.
- "Shared responsibility model" moved from cloud-certification jargon into board-deck vocabulary.
- India's general election ran through the month, with cyber teams on heightened alert throughout.
The login as the new perimeter
Snowflake changed platform defaults across the industry: enforced MFA, mandatory network policies, and credential-hygiene checks that treat an old saved password as the live liability it is. It also marked the point where identity, not the network, became the thing defenders actually guard — the through-line that runs from here to the Salesloft token theft of 2025 and the OAuth campaigns of 2026 documented elsewhere in this archive. The infostealer economy that supplied the credentials only grew, culminating in the sixteen-billion-record compilation that panicked the internet in June 2025. And Ascension joined the permanent case file for why healthcare ransomware is a patient-safety issue before it is an IT one.